Thanks Paul,
I feel Section 3.3. "DNSSEC with Priming Queries" may not do the effects
of redirected query traffic enough justice. RFC 8109 already didn't do
it enough justice I think.
For starters, the second paragraph already assumes a
"machine-in-the-middle" attack, but there may also be o
Internet-Draft draft-ietf-dnsop-rfc8109bis-04.txt is now available. It is a
work item of the Domain Name System Operations (DNSOP) WG of the IETF.
Title: Initializing a DNS Resolver with Priming Queries
Authors: Peter Koch
Matt Larson
Paul Hoffman
Name:draft-